SiteList review score
Delivers exceptional terminal-first utility and performance for security engineers. Mid-funnel content gaps and technical configuration errors limit its reach.
Reviewed on Aug 3, 2026
qsa.sh
Unclaimed listingIs this your site?
Claim itWhat it does
A terminal-based service that performs an external port and vulnerability scan of the user's own public IP address using open-source tools (naabu, nmap, nuclei), offering a free live-streaming tier and paid async/deep scan tiers.
SiteList review score
Delivers exceptional terminal-first utility and performance for security engineers. Mid-funnel content gaps and technical configuration errors limit its reach.
Reviewed on Aug 3, 2026
Verified user rating
—
No verified reviews yet — the evidence locker is empty.
Captured during our latest review on Aug 24, 2026
Free tier available; Full plan is $5/mo via PayPal; Deep scan is a $7 one-time purchase per scan. Billed monthly.
| Plan | Price | Details |
|---|---|---|
| Free | $0 monthly per scan | Live terminal stream, ~30 seconds. Top 1,000 ports, ~2,000 nuclei checks. 1 scan per IP per 24h · Top 1,000 TCP ports only · Open ports, versions & top 3 findings only · Nothing stored View source |
| Full | $5 monthly per subscription | Async delivery. All 65,535 ports + ~2,000 high-signal nuclei checks. 1 scan per hour · Full list + remediation guidance · Single-read or 24h Redis retention View source |
| Deep | $7 one time per scan | Async emailed report. All 65,535 ports + full nuclei template set. Unlimited scans · Full list + remediation, emailed · Single-read or 24h Redis retention View source |
External port scanning
Security scanning
Probes open TCP ports on the user's public IP using naabu and nmap.
Vulnerability detection
Security scanning
Maps service banners to known CVEs using nmap vulners script and nuclei templates.
Live terminal streaming
Delivery method
Streams scan results directly to the user's terminal in real-time.
Zero data retention
Privacy & security
Scan results are ephemeral, streamed only, and never written to disk or stored long-term.
IP opt-out mechanism
Privacy & security
Allows users to permanently exclude their IP or CIDR range from being scanned via a contact form.
Self-audit of public infrastructure
Verifies what external attackers can see of a host's open ports and vulnerabilities.
Terminal-based quick security check
Provides a fast, install-free way for developers to run a surface-level scan directly from the command line.
Yes. The tool uses industry-standard open-source components like nmap and nuclei, providing high transparency for security engineers who need to verify the underlying scan logic.
While Shodan and Censys offer massive global datasets, qsa.sh focuses on frictionless, terminal-native execution for specific IP scans, catering to a 'terminal-first' developer workflow.
The site currently suffers from aggressive no-store caching headers and a noindexed contact page, which impacts performance efficiency and high-intent user conversions.
The business model is freemium with a pay-per-scan option. The tool is highly accessible, and pricing is transparent for the available tiers.
Answers are based on SiteList's latest evidence review. Read the full review.
qsa.sh earns a 86/100, distinguishing itself through an exceptional terminal-first usability and performance profile for security engineers. However, its market growth is currently limited by a critical lack of middle-of-funnel content and technical configuration oversights.
86/100: Exceptional technical utility hindered by content gaps and configuration errors.
No reviews yet. The evidence locker is empty.
Reviews from verified users appear here once approved.
Reviews are from the SiteList community. Some reviewers received incentives — disclosed in the review, always. The verdict is never for sale.
Home
Fixvibe screenshot 1 of 4: Home
fixvibe.app
Security scanner for AI-generated web apps, including DAST, BaaS misconfiguration checks, leaked-secret detection, and AI-ready remediation prompts.
Home
VulnWatch Agency — Branded website security reports for digital agencies screenshot 1 of 4: Home
vulnwatch.tech
VulnWatch is an automated website vulnerability scanner that uses a proprietary AI Analyst module to transform raw scanner data into prioritized security reports. It provides executive summaries, ranked risks, and actionable remediation plans for web applications, WordPress sites, and network services.
codecanary.org
Client-side browser fingerprinting diagnostic tool that runs live measurements in the browser and displays collected signals for identifiability assessment.
Home
Duckduckgoose screenshot 1 of 4: Home
duckduckgoose.ai
DuckDuckGoose builds explainable deepfake detection for identity, fraud and compliance teams, backing every verdict with forensic evidence.